Live data from Hacker News

Delve – Fake Compliance as a Service

deepdelver.substack.com

251–260 of 327 posts

Re: Delve – Fake Compliance as a Service

#251
post #91

Earlier quoted context omitted.

> thinking they wish to pay taxes Wellll this is not always the case. I have moved from a shithole country to a nice one and oh boy I am crying in gratitude every month that I pay taxes. Because it is every day that I can see my money working for me in the environment. But your point stands.

There are well-used tax money, then there are stupidly burned tax money on ie buying favors of some part of population before elections, financing blindly without any checks social security programs that get abused to no end, or simply plain old corruption. I love bringing Switzerland up to annoy most of western/northern Europeans since their success is so obvious and undeniable while going in very different directio…

> Do you think lets say a heavy tax burden in say Italy, or even France [] is really used well and efficiently?

Those two countries are textbook examples of ineffective state taxation-wise. Similar insane tax burden can be found in Scandinavian countries but at the same time these are the happiest countries in the world [1].

And I live in Poland where taxes are used efficiently. Or so it seems on a daily basis.

[1] https://worldpopulationreview.com/country-rankings/happiest-...

Re: Delve – Fake Compliance as a Service

#252
post #91

Earlier quoted context omitted.

There are well-used tax money, then there are stupidly burned tax money on ie buying favors of some part of population before elections, financing blindly without any checks social security programs that get abused to no end, or simply plain old corruption. I love bringing Switzerland up to annoy most of western/northern Europeans since their success is so obvious and undeniable while going in very different directio…

>Low to low-medium taxes, yet state budgets are frequently in positive numbers >because population is not hard comfort-zone-addicted and entitled bunch of spoiled whiny kids I'm not sure why would I need lower taxes in exchange for more work. This somehow feels like a scam.

Hmm this is surely a brain teaser and not a serious comment. More work as in 40 hours of work, or less if you agree sub-100% contract, ie I have 90% and 10 weeks of paid vacation. And less taxes mean more money for you if you didn't catch that part, that you can invest ie in working less, or retire earlier.

The fact the country runs better than literally anything else in European continent is motivating enough for many folks. Higher quality free education, better healthcare, lower criminality, country simply has better future when looking at past and current situation. I am more than happy to put the same 40h work week I would be working mostly elsewhere, to give my kids a (much) better start in life, and to give the same better life to myself. Easy deal, but please stay at home and be happy if you are, I am not selling this country just showing other, sometimes inconvenient facts.

Re: Delve – Fake Compliance as a Service

#253
post #78
post #65

Earlier quoted context omitted.

When I worked in cybersecurity I had a similar realization. No one cared about security posture. They cared about insurance policies. People hired us to shift blame instead of improve security posture. this is not terribly different

This is why I've said for years: If you want to drive best practices and policy with companies you can only do it with liability. Particularly non-insurable and non-tax deductible liability. If a company can't offload civil or criminal penalties to their insurance company and take the tax write down, they suddenly start caring about it. That said, this should be used sparingly; as it embeds a behavior deep. If that b…

On an emotional level I feel the same way: I would love the company who leaked my PII die and their CEO/CTO be out of job forever.

Practically I think that leaking data is inevitable. A junior developer absolutely WILL vibecode a piece of code with glaring security vulnerabilities. An experienced sysadmin WILL temporarily allow public access to the S3 bucket and then forget.

So if you make sure liabilities are covered by corporate assets and are uninsurable, you will find out a world with no services soon.

I don't know what middle ground is possible to find here.

Re: Delve – Fake Compliance as a Service

#255
post #91

Earlier quoted context omitted.

There are well-used tax money, then there are stupidly burned tax money on ie buying favors of some part of population before elections, financing blindly without any checks social security programs that get abused to no end, or simply plain old corruption. I love bringing Switzerland up to annoy most of western/northern Europeans since their success is so obvious and undeniable while going in very different directio…

> Do you think lets say a heavy tax burden in say Italy, or even France [] is really used well and efficiently? Those two countries are textbook examples of ineffective state taxation-wise. Similar insane tax burden can be found in Scandinavian countries but at the same time these are the happiest countries in the world [1]. And I live in Poland where taxes are used efficiently. Or so it seems on a daily basis. [1] h…

Yeah Poland's growth is very respectable, keep it up and become economic tiger of EU. Most of western EU is ossificated and can't act fast enough in global market economy. Germans are starting to feel whats coming for their economy and it isn't nice.

Re: Delve – Fake Compliance as a Service

#256
post #245

Earlier quoted context omitted.

If someone checked one box, and the company goes under because of a lawsuit linked to not doing what this box said, then the individual who checked that box becomes personally liable of the damages done to the shareholders asset (the value of the company). You don't want to be in this position, really. And that's the whole point of compliance.

Maybe. If their boss told them to do it and their boss is the CEO, probably not. It's on the prosecutor to prove the individual employee committed a crime worthy of piercing the corporate veil.

> If their boss told them to do it and their boss is the CEO, probably not

Then it becomes the CEO who's responsible. “Compliance” is there to protect the shareholders!

Re: Delve – Fake Compliance as a Service

#257
post #65

Earlier quoted context omitted.

When I worked in cybersecurity I had a similar realization. No one cared about security posture. They cared about insurance policies. People hired us to shift blame instead of improve security posture. this is not terribly different

I think it's subtly different than that. Companies do want to be secure. They try, and they often fail because it's hard . They hire auditors to find problems and to shift blame. But since they only have 30 days to fix the problems that are found, it's going to see a lot like they only care about shifting the blame. Because at that point, they only care about passing that audit. Right after that, though, they start c…

> Companies do want to be secure.

I'm not sure about that.

Leaking customers' data bears no meaningful penalties and has no repercussions while securely storing said data costs money, add frictions and brings nothing but expenses to the bottom line.

Many companies will make a wise business decision to never spend a single cent in the direction of security and safety of data.

Re: Delve – Fake Compliance as a Service

#258
post #95

Compliance is something that no one ever wants and everybody hates. Not a single founder wakes up in the morning thinking to themselves: "oh I wish I could make my company XYZ-123 compliant!" Thus providing compliance is really just paying someone to shift responsibility. The regulator can ask whether you are compliant. You can present certificate from Delve or someone else and that's the end of it.

> Not a single founder wakes up in the morning thinking to themselves: "oh I wish I could make my company XYZ-123 compliant!" Somehow I doubt that you are in the B2B/Enterprise space. When you're pitching demos and you hear from people "we really wish we could buy your product but we can't because Finance won't approve the expenditure unless you get XYZ-123", and you hear that over and over again because that is the…

I think we are confusing something here.

> we really wish we could buy your product but we can't because Finance won't approve the expenditure unless you get XYZ-123

So you are not dreaming about XYZ-123 compliance, you are dreaming about being able to make sales to corporate entities.

This is a subtle semantic difference.

> there are founders who wake up in the morning wishing

Wishing juicy corporate customers. Not the XYZ-123 compliance per se.

> Compliance is you demonstrating to your customers that you give enough

money and time to emulate the asinine requirements of detrimental standards to pursue corporate sales instead of directing said resources to make your product better.

Re: Delve – Fake Compliance as a Service

#259

Compliance is something that no one ever wants and everybody hates. Not a single founder wakes up in the morning thinking to themselves: "oh I wish I could make my company XYZ-123 compliant!" Thus providing compliance is really just paying someone to shift responsibility. The regulator can ask whether you are compliant. You can present certificate from Delve or someone else and that's the end of it.

Here's me founding a company and thinking "Shit I really need to be on ITIL 4 and ISO9000 before I even consider taking this to market", but I guess we move in different circles.

Do you really want to be compliant to ITIL 4 or do you want to sell to your target market?

I'm pretty sure you want customers who pay money, and ITIL 4 badge is just a small mean to achieve that, not a goal per se.

Post reply on HN